Article Search By : Nurrul Syakira Bakhtiar | Accountant | Internal Audit Division UPM
The increasing prevalence of cyber threats has made cybersecurity governance a critical priority, particularly in the public sector. Cyber incidents can disrupt operations and potentially affect essential service delivery, public safety, and public trust.
Effective governance should ensure that cyber risks are managed systematically through clear accountability, decision-making structures, risk ownership, mitigation plans, and oversight mechanisms.
Key Challenges in the Public Sector
Public sector organisations often face several challenges that can weaken cybersecurity governance, including:
These challenges make clear roles, responsibilities, and management oversight increasingly important.
The Role of Internal Audit
Internal audit plays an important role in assessing whether cybersecurity governance structures are appropriately designed and operating as intended. The focus should not be limited to technology, but should also consider how cyber risks, responsibilities, and information are managed across the organisation.
Key areas of attention include:
Assessing Actual Implementation
The existence of policies and organisational structures alone is not sufficient. Internal audit should also assess whether actual practices are consistent with documented responsibilities.
Interviews and walkthroughs with relevant stakeholders can help identify gaps between policy and practice. This is particularly important because the true owner of a cyber risk may not always be the information technology function, especially where the risk relates to data, operational processes, or responsibilities held by other departments.
Risk Management and Reporting
Good governance also depends on how risks are identified, assessed, and monitored. Internal audit can evaluate whether:
Dashboards, key performance indicators, incident reports, and compliance updates are among the key sources of information that support effective management decision-making.
The Human Element Matters Too
Cybersecurity is not solely a technology issue. Awareness, competency, communication, and clarity of human responsibilities also play an important role in ensuring that controls operate effectively.
Overall, effective cybersecurity governance requires a combination of clear structures, defined risk ownership, continuous oversight, and reliable information. Through systematic assessment, internal audit can help organisations identify governance gaps, strengthen accountability, and improve the effectiveness of cyber risk management.
Source: “Why Cybersecurity Governance Matters” oleh Logan Wamsley. | Laman web: https://internalauditor.theiia.org
Date of Input: 27/08/2026 | Updated: 27/08/2026 | faiz_suparman

Tingkat 2,
Blok F, Bangunan Sekolah Perniagaan dan Ekonomi(SPE),
Jalan Persiaran Tulang Daing,
Universiti Putra Malaysia,
43400 Serdang.